Executive brief
better-helperjs, a library used for building web applications, contains a security flaw in its production static file server. An attacker can exploit this to read sensitive files from the server that are stored in folders adjacent to the public web directory. This could lead to the exposure of private data, configuration files, or credentials if they share a similar naming pattern with the public folder.
Technical details
A directory traversal vulnerability exists in the `safeStaticPath()` method within `src/ssr/site-server.ts` of better-helperjs. The vulnerability stems from using `String.prototype.startsWith()` to validate resolved file paths against the intended root directory. Because this check performs a string comparison rather than a structural path comparison, an attacker can bypass the restriction by requesting paths in adjacent directories that share the same prefix as the root directory (e.g., accessing `/app/dist/client-secrets/` when the root is `/app/dist/client/`). This is exploitable in production environments where the custom static server engine is active. The issue is fixed in version 3.0.6 by ensuring the validation includes a proper path separator.
Affected products
- Rigby-Foundation better-helperjs <= 3.0.5
Timeline
- 2026-05-23: disclosed: Advisory published by TurboRigby
- 2026-06-26: advisory: GitHub Advisory published/reviewed
- 2026-06-26: patched: Fix released in version 3.0.6